"AI makes it much easier for an attacker to create and modify scripts targeting PLCs, so the barrier to attacking industrial systems continues to fall," said Benny Czarny, CEO and founder of OPSWAT, summing up a warning published by U.S. agencies on August 19.
How AI is being used against Siemens S7 Series PLCs
A joint advisory published on August 19 by CISA, the FBI and partner agencies warns that threat actors are deploying artificial intelligence to generate exploitation scripts that target Siemens S7 Series programmable logic controllers (PLCs). According to the advisory, attackers use AI not only to create initial-exploitation code but also to assist with post‑exploitation tasks such as lateral movement and evasion of detection.
The agencies report that these AI-supported tools can leverage open-source industrial automation libraries and mimic legitimate OT monitoring solutions, enabling them to read and write Siemens S7 Series PLC memory, configuration data, and ladder logic programs using the S7comm protocol.
Observed tactics: scanning, AI scripting, and persistent reconnaissance
Investigators observed threat actors using legitimate internet-scanning services—specifically Censys and ZoomEye—to locate Internet-exposed or insufficiently segmented Siemens S7 Series PLCs. Once discovered, AI-generated scripts are used to locate exploits against those devices. The authoring agencies state that PLCs exposed to the internet are at high risk for exploitation.
After gaining access, the advisory says actors have employed AI to improve lateral movement and evade defenses, and to refine tools that provide persistent reconnaissance. “For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts,” the advisory read.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildUrgent mitigations from CISA, the FBI, and partner agencies
The advisory sets out immediate, specific steps for ICS owners and operators. Key recommendations include:
- Hunt proactively for indicators of compromise such as connections from non‑engineering workstations, repeated connection attempts with varying parameters, and connections originating from unexpected countries or IP ranges not associated with vendors or integrators.
- Conduct an immediate inventory of all Siemens S7 Series PLCs and apply critical patches for affected devices.
- Ensure PLCs are not accessible from the internet and separate OT and IT networks.
- Strengthen access controls by restricting PLC access to authorized engineering workstations and enabling multifactor authentication for all remote access to OT networks.
- Disable web servers and unused communication protocols on Siemens S7 Series devices and contact Siemens for model‑specific hardening recommendations.
How ICS owners, third‑party service providers, and system integrators are affected
The advisory emphasizes particular risk where third‑party service providers or system integrators have remote access to PLCs. Asset owners may not realize their systems are exposed when vendors or integrators maintain access, creating an avenue for exploitation. As a result, owners and operators are urged to verify remote access arrangements and ensure that third parties follow the hardening and segmentation steps laid out by the agencies.
Benny Czarny: baseline controls matter more than AI detection
Benny Czarny, CEO and founder of OPSWAT, told the agencies' advisory that while AI lowers the technical barrier for attackers, the fundamental problem remains weak baseline security. “But for me the answer is not simply better AI detection. So yes, AI makes this more urgent. But the real lesson for me is still the same: stop giving attackers a path to the critical system in the first place. And do not rely on antivirus and sandboxes to protect your data flow,” he advised.
The advisory follows earlier U.S. government warnings that Iranian hackers were targeting internet‑exposed industrial systems across brands including Rockwell Automation, Allen‑Bradley, Schneider Electric and Siemens, and comes after reports in early August that water systems across multiple U.S. states had been targeted by suspected Iranian state‑backed hackers. The authoring agencies say the observed AI-driven activity is likely intended to produce persistent reconnaissance and to prepare systems for future disruptive write operations.
The immediate takeaway from the advisory is blunt: operators using Siemens S7 Series PLCs should assume exposure is possible, inventory and patch devices now, and close remote access paths that could be abused. Whether those measures will be implemented quickly enough to counter AI‑assisted, persistent reconnaissance in critical sectors such as water and energy remains the practical question posed by the agencies' findings.
https://www.infosecurity-magazine.com/news/ics-ai-attacks-siemens/




